Kibana 9.4.4 Security Update (ESA-2026-70)

Authorization Bypass Through User-Controlled Key in Kibana Leading to Information Disclosure

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplied identifiers that reference scheduled query result data from Kibana Spaces the requester is not authorized to access.

Affected Versions:

  • 9.x: All versions from 9.4.0 up to and including 9.4.3

Users on the 8.x and 9.0.x through 9.3.x release lines are not affected. The scheduled query result retrieval functionality that contains this vulnerability was introduced in 9.4.0 and is not present in prior release lines. Users on the 9.5.x release line are not affected; the first release of this line (9.5.0) shipped with the fix applied.

Affected Configurations:

  • Kibana deployments with the Osquery Manager integration and multiple Kibana Spaces configured.

Solutions and Mitigations:

The issue is resolved in version 9.4.4.

For Users that Cannot Upgrade:

  • There are no workarounds for this vulnerability.

Indicators of Compromise (IOC)

No specific indicators of compromise have been identified for this vulnerability.

Elastic Cloud Serverless

Due to our continuous deployment and patching model, the vulnerability described in this security advisory was remediated in our Elastic Cloud Serverless offering before the public disclosure.

Severity: CVSSv3.1: Medium ( 4.3 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVE ID: CVE-2026-63259
Problem Type: CWE-639 - Authorization Bypass Through User-Controlled Key